Privacy policy
Online Marketing
We process personal data for the purposes of online marketing, which particularly includes the marketing of advertising space or the display of advertising and other content (collectively referred to as "content") based on the potential interests of users, as well as measuring their effectiveness.
For these purposes, so-called user profiles are created and stored in a file (so-called "cookie") or similar methods are used, by means of which the information relevant for the display of the aforementioned content is stored about the user. This information can include, for example, viewed content, visited websites, used online networks, but also communication partners and technical information such as the browser used, the computer system used, as well as information about usage times. If users have consented to the collection of their location data, this data may also be processed.
The IP addresses of users are also stored. However, we use available IP masking procedures (i.e., pseudonymization by shortening the IP address) to protect users. In general, no clear data of users (such as email addresses or names) are stored within the scope of online marketing procedures, but pseudonyms. This means that neither we nor the providers of the online marketing procedures know the actual identity of the users, but only the information stored in their profiles.
The information in the profiles is usually stored in cookies or by similar methods. These cookies can later generally also be read on other websites that use the same online marketing procedure, analyzed for the purpose of content presentation, supplemented with additional data, and stored on the server of the online marketing procedure provider.
Exceptionally, clear data can be assigned to profiles. This is the case, for example, when users are members of a social network whose online marketing procedures we use and the network links the users' profiles with the aforementioned information. Please note that users can make additional agreements with the providers, e.g., by giving consent during registration.
We generally only receive access to aggregated information about the success of our advertisements. However, within the scope of so-called conversion measurements, we can check which of our online marketing methods have led to a so-called conversion, i.e., for example, to a contract conclusion with us. The conversion measurement is used solely for analyzing the success of our marketing measures.
Unless otherwise specified, please assume that the cookies used are stored for a period of two years.
Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is the consent. Otherwise, the users' data is processed based on our legitimate interests (i.e., interest in efficient, economical, and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
Facebook Pixel: With the help of the Facebook Pixel, Facebook is able, on the one hand, to identify the visitors of our online offer as a target group for displaying advertisements (so-called "Facebook Ads"). Accordingly, we use the Facebook Pixel to show the Facebook Ads placed by us only to such users on Facebook and within the services of partners cooperating with Facebook (the so-called "Audience Network"). https://www.facebook.com/audiencenetwork/ ) to display to users who have also shown an interest in our online offer or who exhibit certain characteristics (e.g., interest in specific topics or products, as indicated by the websites visited) that we transmit to Facebook (so-called "Custom Audiences"). With the help of the Facebook Pixel, we also want to ensure that our Facebook ads correspond to the potential interests of users and do not appear intrusive. Furthermore, the Facebook Pixel allows us to track the effectiveness of Facebook advertisements for statistical and market research purposes by seeing whether users were redirected to our website after clicking on a Facebook ad (so-called "conversion tracking").
- Processed data types: Usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses), location data (data indicating the location of an end user's device), contact data (e.g., email, phone numbers).
- Affected persons: Users (e.g., website visitors, users of online services), prospects, customers.
- Purposes of processing: Tracking (e.g., interest-/behavior-based profiling, use of cookies), remarketing, visit action analysis, interest-based and behavior-based marketing, profiling (creating user profiles), conversion measurement (measuring the effectiveness of marketing measures), reach measurement (e.g., access statistics, recognition of returning visitors), audience formation (determining target groups relevant for marketing purposes or other content delivery), cross-device tracking (cross-device processing of user data for marketing purposes), contact inquiries and communication, direct marketing (e.g., via email or postal mail), audience formation, management and response to inquiries.
- Safety measures: IP masking (pseudonymization of the IP address).
- Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
- Opt-out option: We refer to the privacy notices of the respective providers and the objection options (so-called "opt-out") provided by the providers. If no explicit opt-out option is specified, you can disable cookies in your browser settings. However, this may restrict the functionality of our online offer. Therefore, we additionally recommend the following opt-out options, which are offered collectively for the respective regions: a) Europe: https://www.youronlinechoices.eu . b) Canada: https://www.youradchoices.ca/choices . c) USA: https://www.aboutads.info/choices . d) Cross-regional: https://optout.aboutads.info.
Used services and service providers:
- Google Tag Manager: Google Tag Manager is a solution that allows us to manage so-called website tags through an interface and thus integrate other services into our online offering. The Tag Manager itself (which implements the tags) does not process any personal data of the users. With regard to the processing of users' personal data, reference is made to the following information about the Google services. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy.
- Google Analytics: Online marketing and web analysis; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com/intl/en/about/analytics/; Privacy Policy: https://policies.google.com/privacy; Possibility to object (Opt-Out): Opt-Out plugin: https://tools.google.com/dlpage/gaoptout?hl=en , Settings for the display of advertisements: https://adssettings.google.com/authenticated.
- Google Ads and Conversion Tracking: We use the online marketing method "Google Ads" to place ads in the Google advertising network (e.g., in search results, in videos, on websites, etc.) so that they are shown to users who are presumed to be interested in the ads. Furthermore, we measure the conversion of the ads. However, we only learn the anonymous total number of users who clicked on our ad and were redirected to a page equipped with a so-called "conversion tracking tag." We ourselves do not receive any information that would allow users to be identified. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://marketingplatform.google.com; Privacy Policy: https://policies.google.com/privacy.
- Facebook Pixel: Service provider: https://www.facebook.com, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, Parent Company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Possibility to object (Opt-Out): https://www.facebook.com/settings?tab=ads.
- Pipedrive: Cloud-based software for organizing and optimizing our customer and partner relationships as well as managing incoming emails and information requests; service provider: Pipedrive OÜ, Paldiski mnt 80, Tallinn 10617, Estonia; website: https://www.pipedrive.com/en; Privacy Policy: https://www.pipedrive.com/en/privacy.
Review Platforms
We participate in evaluation procedures to assess, optimize, and promote our services. When users rate us through the involved review platforms or procedures or provide feedback in other ways, the general terms and conditions or terms of use and the privacy policies of the providers also apply. As a rule, the review also requires registration with the respective providers.
To ensure that the reviewers have actually used our services, we transmit the necessary data regarding the customer and the service used to the respective review platform (including name, email address, and order number or item number) with the customer's consent. This data is used solely to verify the authenticity of the user.
- Processed data types: Contract data (e.g., contract subject, duration, customer category), usage data (e.g., visited websites, interest in content, access times), meta-/communication data (e.g., device information, IP addresses).
- Affected persons: Customers, users (e.g., website visitors, users of online services).
- Purposes of processing: Feedback (e.g., collecting feedback via online form).
- Legal basis: Consent (Art. 6 para. 1 sentence 1 lit. a GDPR), Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR).
Presence on Social Networks (Social Media)
We maintain online presences within social networks and process user data in this context to communicate with users active there or to provide information about us.
We point out that user data may be processed outside the territory of the European Union. This may pose risks for users, as, for example, the enforcement of users' rights could be made more difficult.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created based on user behavior and resulting interests. These usage profiles can, in turn, be used to display advertisements within and outside the networks that presumably match the users' interests. For these purposes, cookies are usually stored on users' computers, in which the usage behavior and interests of the users are saved. Additionally, data independent of the devices used by the users can also be stored in the usage profiles (especially if the users are members of the respective platforms and are logged in).
For a detailed description of the respective processing methods and the options to object (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.
Also in the case of information requests and the assertion of data subject rights, we point out that these can be most effectively asserted with the providers. Only the providers have access to the users' data and can directly take appropriate measures and provide information. If you still need assistance, you can contact us.
- Processed data types: Inventory data (e.g., names, addresses), contact data (e.g., email, phone numbers), content data (e.g., text entries, photographs, videos), usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses).
- Affected persons: Users (e.g., website visitors, users of online services).
- Purposes of processing: Contact inquiries and communication, tracking (e.g., interest-/behavior-based profiling, use of cookies), remarketing, reach measurement (e.g., access statistics, recognition of returning visitors).
- Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f. GDPR).
Used services and service providers:
- Instagram : Social network; Service provider: Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA; Website: https://www.instagram.com; Privacy Policy: https://instagram.com/about/legal/privacy.
- Facebook: Social network; Service provider: Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, Parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Option to object (Opt-Out): Settings for advertisements: https://www.facebook.com/settings?tab=ads; Additional notes on data protection: Agreement on joint processing of personal data on Facebook pages: https://www.facebook.com/legal/terms/page_controller_addendum , Privacy Policy for Facebook Pages: https://www.facebook.com/legal/terms/information_about_page_insights_data.
- LinkedIn: Social network; Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Possibility to object (Opt-Out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
- YouTube: Social network; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Privacy policy: https://policies.google.com/privacy; Possibility to object (Opt-Out): https://adssettings.google.com/authenticated.
- Xing: Social network; Service provider: XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany; Website: https://www.xing.de; Privacy Policy: https://privacy.xing.com/en/privacy-policy.
Plugins and embedded functions as well as content
We integrate functional and content elements into our online offering that are sourced from the servers of their respective providers (hereinafter referred to as "third parties"). These may include, for example, graphics, videos, or social media buttons as well as posts (hereinafter collectively referred to as "content").
The integration always assumes that the third-party providers of this content process the users' IP addresses, as they could not send the content to their browsers without the IP address. The IP address is therefore necessary for the display of this content or functions. We strive to use only such content whose respective providers use the IP address solely for delivering the content. Third parties may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. Through the "pixel tags," information such as visitor traffic on the pages of this website can be evaluated. The pseudonymous information can also be stored in cookies on the users' devices and may include, among other things, technical information about the browser and operating system, referring websites, visit time, as well as other details about the use of our online offer, and can be linked with such information from other sources.
Notes on Legal Bases: If we ask users for their consent to the use of third-party providers, the legal basis for data processing is the consent. Otherwise, the users' data is processed based on our legitimate interests (i.e., interest in efficient, economical, and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Processed data types: Usage data (e.g., visited websites, interest in content, access times), meta/communication data (e.g., device information, IP addresses), location data (data indicating the location of an end user's device), contact data (e.g., email, phone numbers), content data (e.g., text entries, photographs, videos), inventory data (e.g., names, addresses).
- Affected persons: Users (e.g., website visitors, users of online services), communication partners.
- Purposes of processing: Provision of our online offer and user-friendliness, contractual services and service, contact inquiries and communication, direct marketing (e.g. by e-mail or postal mail), tracking (e.g. interest-/behavior-based profiling, use of cookies), interest-based and behavior-based marketing, profiling (creating user profiles), security measures, management and response to inquiries.
- Legal basis: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f GDPR), consent (Art. 6 para. 1 sentence 1 lit. a GDPR), contract performance and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b GDPR).
Used services and service providers:
- Facebook plugins and content: Facebook Social Plugins and Content – This can include content such as images, videos, or texts and buttons that allow users to share content from this online offer within Facebook. The list and appearance of the Facebook Social Plugins can be viewed here: https://developers.facebook.com/docs/plugins/; Service provider: https://www.facebook.com, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, Parent company: Facebook, 1 Hacker Way, Menlo Park, CA 94025, USA; Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Option to object (Opt-Out): Settings for advertisements: https://www.facebook.com/settings?tab=ads.
- Google Fonts: We embed the fonts ("Google Fonts") from the provider Google, whereby the users' data is used solely for the purpose of displaying the fonts in the users' browsers. The integration is based on our legitimate interests in a technically secure, maintenance-free, and efficient use of fonts, their uniform presentation, and taking into account possible licensing restrictions for their integration. Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://fonts.google.com/; Privacy Policy: https://policies.google.com/privacy.
- Google Maps: We embed the maps of the service "Google Maps" provided by Google. The data processed may include, in particular, IP addresses and location data of users, which, however, are not collected without their consent (usually given within the settings of their mobile devices); service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://cloud.google.com/maps-platform; Privacy Policy: https://policies.google.com/privacy; Possibility to object (Opt-Out): Opt-Out plugin: https://tools.google.com/dlpage/gaoptout?hl=en , Settings for the display of advertisements: https://adssettings.google.com/authenticated.
- Google Maps APIs and SDKs: Interfaces to the map and location services of Google, which allow, for example, the completion of address entries, location determinations, distance calculations, or the provision of additional information about locations and other places; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; website: https://cloud.google.com/maps-platform; Privacy Policy: https://policies.google.com/privacy.
- Instagram plugins and content: Instagram plugins and content – This may include content such as images, videos, or texts and buttons that allow users to share content from this online offer within Instagram. Service provider: https://www.instagram.com , Instagram Inc., 1601 Willow Road, Menlo Park, CA, 94025, USA; Website: https://www.instagram.com; Privacy Policy: https://instagram.com/about/legal/privacy.
- LinkedIn plugins and content: LinkedIn plugins and content - This can include content such as images, videos, or texts and buttons that allow users to share content from this online offer within LinkedIn. Service provider: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; Website: https://www.instagram.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Possibility to object (Opt-Out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
- YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Parent company: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; Website: https://www.youtube.com; Privacy Policy: https://policies.google.com/privacy; Possibility to object (Opt-Out): Opt-Out plugin: https://tools.google.com/dlpage/gaoptout?hl=en , Settings for the display of advertisements: https://adssettings.google.com/authenticated.
- Xing plugins and buttons: Xing plugins and buttons – This may include content such as images, videos, or texts, as well as buttons that allow users to share content from this online offering on Xing. Service provider: XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany; Website: https://www.xing.com; Privacy Policy: https://privacy.xing.com/en/privacy-policy.
Deletion of Data
The data we process is deleted in accordance with legal requirements as soon as the consents permitting their processing are revoked or other permissions cease to apply (e.g., if the purpose of processing this data no longer exists or they are not required for the purpose).
Unless the data is deleted because it is required for other legally permissible purposes, its processing will be limited to these purposes. This means that the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons or whose storage is necessary for asserting, exercising, or defending legal claims or for protecting the rights of another natural or legal person.
Further information regarding the deletion of personal data may also be provided within the individual data protection notices of this privacy policy.
Change and Update of the Privacy Policy
We ask you to regularly inform yourself about the content of our privacy policy. We adjust the privacy policy as soon as changes in the data processing we carry out make this necessary. We will inform you as soon as the changes require an action on your part (e.g., consent) or any other individual notification.
If we provide addresses and contact information of companies and organizations in this privacy policy, please note that the addresses may change over time and we ask you to verify the information before making contact.
Rights of the data subjects
You, as the data subject, have various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:
- Right to object: You have the right to object at any time, for reasons arising from your particular situation, to the processing of personal data concerning you that is carried out pursuant to Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on these provisions. If personal data concerning you is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for such advertising purposes; this also applies to profiling insofar as it is related to such direct marketing.
- Right of withdrawal for consents: You have the right to revoke given consents at any time.
- Right of information: You have the right to request confirmation as to whether the relevant data is being processed and to access this data as well as additional information and a copy of the data in accordance with legal requirements.
- Right to rectification: You have the right, in accordance with legal requirements, to request the completion of data concerning you or the correction of incorrect data concerning you.
- Right to deletion and restriction of processing: You have the right, in accordance with legal provisions, to request that data concerning you be deleted without delay, or alternatively, in accordance with legal provisions, to request a restriction on the processing of the data.
- Right to data portability: You have the right to receive data concerning you that you have provided to us in a structured, commonly used, and machine-readable format in accordance with legal requirements, or to request the transmission of such data to another controller.
- Complaint to supervisory authority: You also have the right, in accordance with the legal provisions, to lodge a complaint with a supervisory authority, particularly in the member state of your habitual residence, your workplace, or the place of the alleged infringement, if you believe that the processing of your personal data violates the GDPR.
Definitions of Terms
This section provides an overview of the terms used in this privacy policy. Many of the terms are taken from the law and are primarily defined in Art. 4 GDPR. The legal definitions are binding. The following explanations are intended primarily to aid understanding. The terms are sorted alphabetically.
- Visitor Campaign Evaluation: "Visit action evaluation" (English "Conversion Tracking") refers to a method used to determine the effectiveness of marketing measures. Typically, a cookie is stored on the users' devices within the websites where the marketing measures take place and then retrieved again on the target website. For example, this allows us to track whether the ads we placed on other websites were successful.
- Cross-Device Tracking: Cross-device tracking is a form of tracking in which behavioral and interest information of users is collected across devices in so-called profiles by assigning users an online identifier. This allows user information to be analyzed for marketing purposes regardless of the browsers or devices used (e.g., mobile phones or desktop computers). The online identifier is not linked to clear data such as names, postal addresses, or email addresses with most providers.
- IP Masking: "IP masking" refers to a method in which the last octet, i.e., the last two numbers of an IP address, are deleted so that the IP address can no longer be used to uniquely identify a person. Therefore, IP masking is a means of pseudonymizing processing procedures, especially in online marketing.
- Interest-based and behavioral marketing: Interest-based and/or behavioral marketing refers to the practice of predicting potential user interests in ads and other content as accurately as possible. This is done based on information about their previous behavior (e.g., visiting certain websites and staying on them, purchasing behavior, or interaction with other users), which is stored in a so-called profile. For these purposes, cookies are usually used.
- Conversion Tracking: Conversion tracking is a method used to determine the effectiveness of marketing measures. Typically, a cookie is stored on the users' devices within the websites where the marketing measures take place and then retrieved again on the target website. For example, this allows us to track whether the ads we placed on other websites were successful.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g., cookie), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Profiling: "Profiling" refers to any type of automated processing of personal data that involves using this personal data to analyze, evaluate, or predict certain personal aspects related to a natural person (depending on the type of profiling, this includes information concerning age, gender, location data and movement data, interaction with websites and their content, shopping behavior, social interactions with other people). For profiling purposes, cookies and web beacons are often used.
- Range measurement: Reach measurement (also known as web analytics) is used to evaluate the visitor flows of an online offering and can include the behavior or interests of visitors in certain information, such as content on websites. With the help of reach analysis, website owners can, for example, determine at what times visitors access their website and which content they are interested in. This allows them to better tailor the website content to the needs of their visitors. For the purposes of reach analysis, pseudonymous cookies and web beacons are often used to recognize returning visitors and thus obtain more accurate analyses of the use of an online offering.
- Remarketing: "Remarketing" or "Retargeting" refers to the practice of noting which products a user has shown interest in on a website, for advertising purposes, in order to remind the user of these products on other websites, for example through ads.
- Server monitoring and error detection: With the help of server monitoring and error detection, we ensure the availability and integrity of our online offer and use the processed data to technically optimize our online offer. Performance, utilization, and comparable technical values are processed, which provide information about the stability and any irregularities of our online offer. In the event of errors and irregularities, individual requests from users of our online offer are recorded to identify and resolve sources of problems.
- Tracking: "Tracking" refers to the ability to trace user behavior across multiple online services. Typically, behavioral and interest information related to the online services used is stored in cookies or on the servers of the providers of the tracking technologies (so-called profiling). This information can then be used, for example, to display advertisements to users that are likely to match their interests.
- Responsible: The term "controller" refers to the natural or legal person, authority, institution, or other body that alone or jointly with others determines the purposes and means of processing personal data.
- Processing: "Processing" means any operation or set of operations performed on personal data, whether or not by automated means. The term is broad and practically includes any handling of data, such as collecting, evaluating, storing, transmitting, or deleting.
- Target group formation: Target group formation (or "Custom Audiences") refers to the process of defining target groups for advertising purposes, such as displaying advertisements. For example, based on a user's interest in certain products or topics on the internet, it can be inferred that this user is interested in ads for similar products or the online shop where they viewed the products. "Lookalike Audiences" (or similar target groups) refer to users who are shown content deemed suitable because their profiles or interests presumably match those of the users for whom the profiles were created. For the purpose of creating Custom Audiences and Lookalike Audiences, cookies and web beacons are typically used.